JWT Access Token Format
- iat - Issue Time
- nbf - Not Valid Before
- exp - Expiration Time (claim is not included if token has infinite validity)
- jti - JWT ID (random value)
- random - A random value defined through "OAuth 2.0 Token Generator Settings" for the token entropy
- scope - A JSON array defining the scope of the access token
includeSubjectClaim) sub). issuer) iss). If left empty the claim will not be included. audience) The audience claim (aud) to include. If left empty the claim will not be included.
If there is one audience, the claim is written as a string, for multiple values as an array.
notValidBeforeSkew) nbf). scopesAsSpaceSeparatedString) scope claim will be issued as a string array, even if it only contains a single value. customClaims) Custom claims to include in the JWT.
Multiple claims with the same name can be configured if each has a claim condition which ensures that only one of them will be included at runtime.
The following claims are automatically set by Airlock IAM and therefore will be ignored if defined as custom claim.issaudexpnbfiatjtirandomscope
Note: When "Persist Claims" is disabled, custom claims are collected when the Access Token is requested by an OAuth 2.0 client and not when the Access Token is issued. Therefore the values of the custom claims may change between issue and request time.
distributedClaims) Distributed Claims to add to the JWT.
These claims allow providing a URL to a 3rd party claims provider in the response where additional claims may be obtained.
signature) Security Warning: The signature must be verified by the consumer of the JWT before the content is interpreted. When using "JWT Access Token No Signature", the consumer must not trust the content of the JWT and therefore not use it as authenticated data.
Security Warning: Verifying the signature and validity of the self-contained JWT is not sufficient to validate the access token. The access token might have been revoked and thus consumers must verify the validity of the access token (e.g. using Token Introspection) before being used for access control.
type: JwtAccessTokenFormat
id: JwtAccessTokenFormat-xxxxxx
displayName:
comment:
properties:
audience:
customClaims:
distributedClaims:
includeSubjectClaim: false
issuer:
notValidBeforeSkew: 5
scopesAsSpaceSeparatedString: true
signature: